Native
Nothing between you and the socket
The old QueryFlow Studio ran in a browser, so reaching a database on your own machine meant running a second process to proxy around the sandbox. This one is a native binary that opens the socket itself. The difference is not a percentage.
No agent to install
localhost, a socket file, a bastion host — the app connects the way psql does. The separate helper process is gone.
Streams, never buffers
Exports write row by row, so a table larger than memory exports fine. Paging is keyset-ordered, so pages cannot overlap or skip.
14 MB, one file
No runtime to install, no container, no Node. Drag it to Applications and open it.
The boundary
What actually leaves
Every AI tool asks you to trust it. QueryFlow Studio shows you the payload instead. Before a question is sent, the app tells you which tables it names, how many columns, and whether a single value from your data is in there. Flip the switch and watch the shipment change.
- Connection string never sent
- Every row of your data never sent
- Query history local SQLite
- Schema introspection runs locally
- Results of the query never sent
Names and types only — no row values
The service holds the model key, your plan and your quota. It has never held a credential for your database, because it was never given one.
Ask, explain, describe
Three things you can ask it
Ask for a query and get SQL you can read, edit and run — never a black box that returns rows. Point at any statement and have it explained. Open a table and have every column described. Each answer says what it assumed, and what was sent to get it.
Counts customers by country for the last full quarter, largest first.
Assumed created_at is the signup date and is not null.
select p.sku, sum(oi.qty) as units
from order_items oi
join products p on p.id = oi.product_id
where oi.created_at > now() - interval '30 days'
group by p.sku
order by units desc
limit 20;The twenty best-selling SKUs of the last thirty days, by units. It reads order_items once and joins products by primary key, so the cost is the date filter — an index on order_items(created_at) is what makes or breaks it.
Assumed qty is never negative — returns are elsewhere.
public.customers — one row per shopper. Written by sign-up and by the order pipeline; read by everything.
- id
- Surrogate key; never shown to customers.
- Login identity. Unique, lower-cased on write.
- country
- ISO 3166 code at sign-up; not updated on move.
- orders
- Denormalised count — maintained by a trigger, not a view.
- spend
- Lifetime total in the shop currency. Moves only with orders.
- metadata
- Tier is derived from spend; nothing else lives here yet.
Free with an account: ten prompts a day, all three. Pro raises the limit and is where the next tools land — schema docs, ERDs, and performance advice — as they ship.
Free to use
Get QueryFlow Studio
The client is free and works without an account. Signing in adds the AI features and ten prompts a day; paid plans raise that. Nothing about your databases changes either way.
- Latest releaseDownload
- Latest releaseDownload
- Latest releaseDownload
- Latest releaseDownload
- Latest releaseDownload
Requires PostgreSQL 12 or newer. macOS 12+, Windows 10+, or a glibc 2.31 Linux.
First launch on macOS: "Apple could not verify" or "is damaged"
QueryFlow Studio isn't notarized by Apple yet, so macOS checks with you once. Which dialog you see decides the fix:
"Apple could not verify…" — click Done, openSystem Settings → Privacy & Security, scroll down and clickOpen Anyway. Once is enough.
"…is damaged and can't be opened" — the download's quarantine flag needs clearing. In Terminal:
xattr -d com.apple.quarantine "/Applications/QueryFlow Studio.app"Then open it normally. Neither step changes what the app can do; it only tells macOS you chose to run it.